Description
https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).
Remediation
References
https://hackerone.com/reports/319532
Related Vulnerabilities
CVE-2022-25908 Vulnerability in npm package create-choo-electron
CVE-2023-3635 Vulnerability in maven package com.squareup.okio:okio
CVE-2022-2063 Vulnerability in npm package nocodb
CVE-2023-37912 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-macro-footnotes
CVE-2019-10795 Vulnerability in maven package org.webjars.npm:undefsafe